Starting late January 2025, organizations with enabled passkey (FIDO2) policy and no key restrictions will have passkeys in the Microsoft Authenticator app. Users can add this via aka.ms/MySecurityInfo, and it's enforced by Conditional Access policy. Organizations preferring not to enable this can impose key restrictions.
Entra Authenticator passkeys begin enabling for FIDO2 organizations without key restrictions
January’s supplied evidence contains one substantive Entra update: a Microsoft 365 Message Center major update for Entra ID Authentication. Starting in late January 2025, organizations with an enabled passkey (FIDO2) policy and no key restrictions will have passkeys available in the Microsoft Authenticator app. The notice describes an enablement, but does not identify the capability as preview or generally available.
- Authenticator passkeys enabled for unrestricted FIDO2 policiesMicrosoft Entra ID — Authentication
This is an enablement and behavior change rather than a documentation update. Beginning in late January, passkeys in Microsoft Authenticator become available to organizations whose Entra passkey (FIDO2) policy is enabled and does not specify key restrictions. Users can add the passkey from aka.ms/MySecurityInfo; the supplied notice does not classify the capability as preview or generally available.
In the affected configuration, users can add an Authenticator passkey through aka.ms/MySecurityInfo, and its use is enforced through Conditional Access. Organizations that do not want this enablement can impose key restrictions. No broader rollout scope or additional administrative steps are supplied.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
